{"id":5630,"date":"2025-07-25T10:03:36","date_gmt":"2025-07-25T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/25\/fire-ant-hackers-exploiting-vulnerabilities-in-vmware-esxi-and-vcenter-to-infiltrate-organizations\/"},"modified":"2025-07-25T10:03:36","modified_gmt":"2025-07-25T10:03:36","slug":"fire-ant-hackers-exploiting-vulnerabilities-in-vmware-esxi-and-vcenter-to-infiltrate-organizations","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/25\/fire-ant-hackers-exploiting-vulnerabilities-in-vmware-esxi-and-vcenter-to-infiltrate-organizations\/","title":{"rendered":"Fire Ant Hackers Exploiting Vulnerabilities in VMware ESXi and vCenter to Infiltrate Organizations"},"content":{"rendered":"<p>    Fire Ant Hackers Exploiting Vulnerabilities in VMware ESXi and vCenter to Infiltrate Organizations<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated espionage campaign dubbed \u201cFire Ant\u201d demonstrates previously unknown capabilities in compromising VMware virtualization infrastructure.\u00a0<\/p>\n<p>Since early 2025, this threat actor has systematically targeted VMware ESXi hosts, vCenter servers, and network appliances using hypervisor-level techniques that evade traditional endpoint security solutions.\u00a0<\/p>\n<p>The campaign exhibits strong technical overlap with the previously identified <a href=\"https:\/\/cybersecuritynews.com\/juniper-junos-os-improper-isolation-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">UNC3886<\/a> threat group, employing critical vulnerabilities and custom malware to maintain persistent, stealthy access to organizational networks.<\/p>\n<pre class=\"wp-block-preformatted\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">Key Takeaways<br><\/mark><\/strong>1. Fire Ant exploits critical VMware ESXi and vCenter flaws for undetected hypervisor-level access.\u00a0<br>2. Deploys stealth backdoors and disables logging to maintain persistent control.<br>3. Tunnels via compromised infrastructure to bypass network segmentation and reach isolated assets.<\/pre>\n<h2 class=\"wp-block-heading\"><strong>Advanced VMware Infrastructure Exploitation Techniques<\/strong><\/h2>\n<p>Sygnia <a href=\"https:\/\/www.sygnia.co\/blog\/fire-ant-a-deep-dive-into-hypervisor-level-espionage\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reports<\/a> that Fire Ant\u2019s initial attack vector leverages <a href=\"https:\/\/cybersecuritynews.com\/vmware-vcenter-server-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-34048<\/a>, an out-of-bounds write vulnerability in vCenter Server\u2019s DCERPC protocol implementation that enables unauthenticated remote code execution.\u00a0<\/p>\n<p>Security researchers identified suspicious crashes of the \u2018vmdird\u2019 process on vCenter servers, indicating exploitation of this critical vulnerability.\u00a0<\/p>\n<p>Following successful compromise, the threat actors deploy sophisticated tools, including the open-source script vCenter_GenerateLoginCookie.py, to forge authentication cookies and bypass login mechanisms.<\/p>\n<p>The attackers systematically harvest vpxuser credentials \u2013 system accounts automatically created by vCenter with full administrative privileges over ESXi hosts.\u00a0<\/p>\n<p>This credential theft enables lateral movement across the entire virtualization infrastructure, as vpxuser accounts remain exempt from lockdown mode restrictions.\u00a0<\/p>\n<p>The threat actors also exploit <a href=\"https:\/\/cybersecuritynews.com\/chinese-hackers-exploiting-vmware-esxi-zero-day\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-20867<\/a>, a VMware Tools vulnerability that permits unauthenticated host-to-guest command execution through PowerCLI\u2019s Invoke-VMScript cmdlet.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Persistence Capabilities and Evasion Methods<\/strong><\/h2>\n<p>Fire Ant demonstrates remarkable persistence capabilities through multiple backdoor deployment techniques.\u00a0<\/p>\n<p>The group installs malicious vSphere Installation Bundles (VIBs) with acceptance levels set to \u2018partner\u2019 and deployed using the \u2013force flag to bypass signature validation.\u00a0<\/p>\n<p>These unauthorized VIBs contain configuration files referencing binaries in the \u2018\/bin\u2019 folder and custom scripts embedded in \u2018\/etc\/rc.local.d\/\u2019 for startup execution.<\/p>\n<p>Additionally, the attackers deploy a Python-based HTTP backdoor named autobackup.bin that binds to port 8888 and provides remote command execution capabilities.\u00a0<\/p>\n<p>This malware modifies \u2018\/etc\/rc.local.d\/local.sh\u2019 on ESXi hosts for persistent execution. To further evade detection, Fire Ant terminates the vmsyslogd process, VMware\u2019s native syslog daemon, effectively disabling both local log writing and remote log forwarding.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcP0qrCp2UbPzxYPnxz445GjiKtbPOVspJlauWVvqV0wNnnlOvvq455ye3gRNTtxK0lTXNjeVD48bEDN9_Ggpu_x6cTN9UrmUpy_ImCZj2rSAz_sNWPiti4wiRI9eiEYsSEXtuS?key=Kkrw9JNQI8ru6wsj4hoc_g\" alt=\"\"><\/figure>\n<p>The threat actors demonstrate sophisticated network manipulation capabilities by compromising F5 load balancers through CVE-2022-1388 exploitation, deploying webshells to \u2018<em>\/usr\/local\/www\/xui\/common\/css\/css.php<\/em>\u2018 for network bridging.\u00a0<\/p>\n<p>They utilize Neo-reGeorg tunneling webshells on internal Java-based web servers and deploy the Medusa rootkit on Linux pivot points for credential harvesting and persistent access.<\/p>\n<p>Fire Ant employs netsh portproxy commands for port forwarding through trusted <a href=\"https:\/\/cybersecuritynews.com\/endpoint-security-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">endpoints<\/a>, effectively bypassing access control lists and firewall restrictions.\u00a0<\/p>\n<p>The group also exploits IPv6 traffic to circumvent IPv4-focused filtering rules, demonstrating a comprehensive understanding of dual-stack network environments and common security gaps in organizational infrastructure.<\/p>\n<p>Organizations must urgently prioritize securing their VMware environments through comprehensive patching, enhanced monitoring of hypervisor activities, and implementation of advanced detection capabilities that extend beyond traditional endpoint security solutions.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\">Experience faster, more accurate phishing detection and enhanced protection for your business with real-time sandbox analysis-&gt; <strong><a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jul&amp;utm_medium=article&amp;utm_campaign=freemium-exclusive&amp;utm_content=plans1&amp;utm_term=220725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try ANY.RUN now<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/vmware-esxi-and-vcenter-exploited\/\">Fire Ant Hackers Exploiting Vulnerabilities in VMware ESXi and vCenter to Infiltrate Organizations<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/vmware-esxi-and-vcenter-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fire Ant Hackers Exploiting Vulnerabilities in VMware ESXi and vCenter to Infiltrate Organizations A sophisticated espionage campaign dubbed \u201cFire Ant\u201d demonstrates previously unknown capabilities in compromising VMware virtualization infrastructure.\u00a0 Since early 2025, this threat actor has systematically targeted VMware ESXi hosts, vCenter servers, and network appliances using hypervisor-level techniques that evade traditional endpoint security solutions.\u00a0 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1383,129,63],"tags":[130],"class_list":["post-5630","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-today","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5630"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5630"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5630\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5630"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5630"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5630"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}